CVE-2013-3241

phpMyAdmin <4.0.0-rc3 - Code Injection

Title source: llm
STIX 2.1

Description

export.php (aka the export script) in phpMyAdmin 4.x before 4.0.0-rc3 overwrites global variables on the basis of the contents of the POST superglobal array, which allows remote authenticated users to inject values via a crafted request.

Exploits (1)

exploitdb WRITEUP VERIFIED
by waraxe · textwebappsphp
https://www.exploit-db.com/exploits/25003

References (2)

Core 2
Core References
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2013-04/0217.html

Scores

EPSS 0.0337
EPSS Percentile 87.4%

Details

Status published
Products (1)
phpmyadmin/phpmyadmin 4.0.0 rc2
Published Apr 26, 2013
Tracked Since Feb 18, 2026